4. Ends within the window you set
The security end date falls after the as-at date and within the number of days you set (90 by default, a default and not a rule of any scheme). It is the list to start the upgrades from.
- When it is raised
- security end date after the as-at date and no more than the window of days after it (inclusive); 90 days unless you set another number
- The question
- Which of these can be upgraded before the date shown, and which need a plan approved now?
- For
- your IT operations lead
The clauses it can cite
CIS Controls v8 2.2Ensure Authorized Software is Currently SupportedEnsure Authorized Software is Currently Supported. Only software that still receives vendor support may be marked as authorised in the enterprise software register. Where unsupported software is still needed for the mission, record an exception that sets out the compensating controls and the acceptance of remaining risk. Unsupported software with no recorded exception is to be marked unauthorised. Check the list for support status no less often than monthly.
PCI DSS 4.0 12.3.4Annual review of hardware and software technologies12.3.4 Annual review of hardware and software technologies. Hardware and software in use must undergo a check at least every 12 months, covering at minimum: analysis that vendors still supply timely security fixes; analysis that the technologies still support, and do not obstruct, PCI DSS compliance; documentation of industry announcements or trends about a technology, for instance a vendor's end-of-life notice; and a remediation plan for outdated technologies, including those with announced end-of-life, approved by senior management. Objective under the customized approach: hardware and software stay current and vendor supported, and plans to retire or replace unsupported components are reviewed periodically. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.
NIST SP 800-53 SA-22Unsupported System ComponentsSA-22 Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support for unsupported components [Selection (one or more): in-house support; [Assignment: organization-defined support from external providers]].
ISO/IEC 27001 A.8.8Management of technical vulnerabilitiesManagement of technical vulnerabilities. The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8.